Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

PHPJabbers Car Park Booking System 2.0 Cross Site Scripting

PHPJabbers Car Park Booking System version 2.0 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#vulnerability#web#php#auth
Ubuntu Security Notice USN-5823-3

Ubuntu Security Notice 5823-3 - USN-5823-1 fixed vulnerabilities in MySQL. Unfortunately, 8.0.32 introduced a regression in MySQL Router preventing connections from PyMySQL. This update reverts most of the changes in MySQL Router to 8.0.31 until a proper fix can be found.

PHPJabbers Event Ticketing System Script 1.0 Cross Site Scripting

PHPJabbers Event Ticketing System Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Travel Tours Script 1.0 SQL Injection

PHPJabbers Travel Tours Script version 1.0 suffers from a remote SQL injection vulnerability.

PHPJabbers Travel Tours Script 1.0 Cross Site Scripting

PHPJabbers Travel Tours Script version 1.0 suffers from a cross site scripting vulnerability.

PHPJabbers Property Listing Script 3.1 SQL Injection

PHPJabbers Property Listing Script version 3.1 suffers from a remote SQL injection vulnerability.

PHPJabbers Property Listing Script 3.1 Cross Site Scripting

PHPJabbers Property Listing Script version 3.1 suffers from a cross site scripting vulnerability.

Update your LearnPress plugins now!

Categories: News Tags: wordpress Tags: learnpress Tags: vulnerability Tags: SQL Tags: injection Tags: update Tags: fix Tags: plugin Tags: patch We take a look at reports of a WordPress plugin issue. It's been fixed, but you may need to update! (Read more...) The post Update your LearnPress plugins now! appeared first on Malwarebytes Labs.

CVE-2023-22324

SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.

CVE-2023-0570: online-tours-travels-management-system/user_operations_payment_operation_booking_id.md at main · linmoren/online-tours-travels-management-system

A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file user\operations\payment_operation.php. The manipulation of the argument booking_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219729 was assigned to this vulnerability.